SUSE-SU-2022:3560-1
Dashboard / Vulnerabilities / SUSE-SU-2022:3560-1
SUSE-SU-2022:3560-1
Summary: Security update for snakeyaml
Details: This update for snakeyaml fixes the following issues: snakeyaml was upgraded to version 1.31: - CVE-2022-25857: Fixed DoS due missing to nested depth limitation for collections (bsc#1202932). - CVE-2022-38749: Fixed DoS due to stack overflow in parser (bsc#1202932). - CVE-2022-38751: Fixed DoS due to parsing of untrusted yaml files (bsc#1203153). - CVE-2022-38752: Fixed DoS due to stack overflow in parser (bsc#1203154). - CVE-2022-38750: Fixed DoS due to parsing of untrusted yaml files (bsc#1203158). - CVE-2020-13936: Fixed arbitrary code execution when attacker is able to modify templates (bsc#1183360).
References: https://www.suse.com/support/update/announcement/2022/suse-su-20223560-1/, https://bugzilla.suse.com/1183360, https://bugzilla.suse.com/1202932, https://bugzilla.suse.com/1203149, https://bugzilla.suse.com/1203153, https://bugzilla.suse.com/1203154, https://bugzilla.suse.com/1203158, https://www.suse.com/security/cve/CVE-2020-13936, https://www.suse.com/security/cve/CVE-2022-25857, https://www.suse.com/security/cve/CVE-2022-38749, https://www.suse.com/security/cve/CVE-2022-38750, https://www.suse.com/security/cve/CVE-2022-38751, https://www.suse.com/security/cve/CVE-2022-38752
Affected packages
Package
Name: snakeyaml
Purl: pkg:rpm/suse/snakeyaml&distro=SUSE%20Manager%20Server%20Module%204.1
Affected ranges
Type: ECOSYSTEM
Events:
